{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,3,14]],"date-time":"2024-03-14T18:23:21Z","timestamp":1710440601360},"reference-count":16,"publisher":"SAGE Publications","issue":"7","license":[{"start":{"date-parts":[[2017,7,1]],"date-time":"2017-07-01T00:00:00Z","timestamp":1498867200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["International Journal of Distributed Sensor Networks"],"published-print":{"date-parts":[[2017,7]]},"abstract":"<jats:p> In this article, we analyze the behavioral characteristics of domain name service queries produced by programs and then design an algorithm to detect malware with expired command-and-control domains based on the key feature of domain name service traffic, that is, repeatedly querying domain with a fixed interval. In total, 3027 malware command-and-control domains in the network traffic of Shanghai Jiao Tong University, affecting 249 hosts, were successfully detected, with a high precision of 92.0%. This algorithm can find those malware with expired command-and-control domains that are usually ignored by current research and would have important value for eliminating network security risks and improving network security environment. <\/jats:p>","DOI":"10.1177\/1550147717720791","type":"journal-article","created":{"date-parts":[[2017,7,24]],"date-time":"2017-07-24T06:55:42Z","timestamp":1500879342000},"page":"155014771772079","update-policy":"http:\/\/dx.doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":4,"title":["Detecting malware based on expired command-and-control traffic"],"prefix":"10.1177","volume":"13","author":[{"given":"Futai","family":"Zou","sequence":"first","affiliation":[{"name":"School of Cyberspace Security, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Siyu","family":"Zhang","sequence":"additional","affiliation":[{"name":"Network and Information Center, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Linsen","family":"Li","sequence":"additional","affiliation":[{"name":"School of Cyberspace Security, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Li","family":"Pan","sequence":"additional","affiliation":[{"name":"School of Cyberspace Security, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jianhua","family":"Li","sequence":"additional","affiliation":[{"name":"School of Cyberspace Security, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2017,7,23]]},"reference":[{"key":"bibr1-1550147717720791","volume-title":"Proceedings of the international conference on European transnational education","author":"Queiruga-Dios A"},{"issue":"4","key":"bibr2-1550147717720791","first-page":"159","volume":"6","author":"Chizari H","year":"2014","journal-title":"J Mob Embed Distrib Syst"},{"key":"bibr3-1550147717720791","first-page":"299","volume-title":"Proceedings of the 2009 cybersecurity applications & technology conference for homeland security","author":"Bailey M"},{"key":"bibr4-1550147717720791","first-page":"268","volume-title":"Proceedings of the 3rd international conference on emerging security information systems and technologies","author":"Feily M"},{"key":"bibr5-1550147717720791","first-page":"967","volume-title":"Proceedings of the 32nd annual IEEE international computer software and applications conference","author":"Zhu Z"},{"key":"bibr6-1550147717720791","first-page":"48","volume-title":"Proceedings of the 10th ACM SIGCOMM conference on Internet measurement","author":"Yadav S"},{"key":"bibr7-1550147717720791","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2012.2184552"},{"key":"bibr8-1550147717720791","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2011.05.026"},{"key":"bibr10-1550147717720791","volume-title":"Proceedings of the 2nd DNS-OARC workshop","author":"Liu Z"},{"key":"bibr11-1550147717720791","doi-asserted-by":"publisher","DOI":"10.1145\/2534169.2486018"},{"key":"bibr15-1550147717720791","volume-title":"Proceedings of the DNS-OARC workshop","author":"Gijsen B"},{"key":"bibr20-1550147717720791","first-page":"639","volume-title":"Proceedings of the 16th international world wide web conference","author":"Zhang Y"},{"key":"bibr21-1550147717720791","first-page":"571","volume-title":"Proceedings of the 18th international world wide web conference","author":"Xiang G"},{"key":"bibr22-1550147717720791","first-page":"21","volume-title":"Proceedings of the 27th annual computer security applications conference","author":"Neugschwandtner M"},{"key":"bibr23-1550147717720791","first-page":"635","volume-title":"Proceedings of the 16th ACM conference on computer and communications security","author":"Stone-Gross B"},{"key":"bibr24-1550147717720791","volume-title":"Proceedings of the 5th USENIX workshop on large-scale exploits and emergent threats","author":"Dittrich D"}],"container-title":["International Journal of Distributed Sensor Networks"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/1550147717720791","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/journals.sagepub.com\/doi\/full-xml\/10.1177\/1550147717720791","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/1550147717720791","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,1,5]],"date-time":"2021-01-05T04:42:36Z","timestamp":1609821756000},"score":1,"resource":{"primary":{"URL":"http:\/\/journals.sagepub.com\/doi\/10.1177\/1550147717720791"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,7]]},"references-count":16,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2017,7]]}},"alternative-id":["10.1177\/1550147717720791"],"URL":"https:\/\/doi.org\/10.1177\/1550147717720791","relation":{},"ISSN":["1550-1477","1550-1477"],"issn-type":[{"value":"1550-1477","type":"print"},{"value":"1550-1477","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,7]]}}}